Over Security

Over Security

CISA orders urgent action on actively exploited Langflow RCE flaw
CISA orders urgent action on actively exploited Langflow RCE flaw
The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents.
·bleepingcomputer.com·
CISA orders urgent action on actively exploited Langflow RCE flaw
Il caso OpenAI-Hugging Face: l’AI ha già imparato ad aggirare le sandbox
Il caso OpenAI-Hugging Face: l’AI ha già imparato ad aggirare le sandbox
Durante un test in ambiente isolato, modelli avanzati di OpenAI hanno individuato e sfruttato una vulnerabilità zero-day per ottenere l'accesso a Internet e compromettere i server di Hugging Face. Un episodio che ridefinisce i limiti delle sandbox e i modelli di difesa nell'era dell'AI
·cybersecurity360.it·
Il caso OpenAI-Hugging Face: l’AI ha già imparato ad aggirare le sandbox
Stop renting storage space — this lifetime 2TB plan is yours for $59
Stop renting storage space — this lifetime 2TB plan is yours for $59
Cloud storage costs tend to creep up over time, since most services charge monthly or annually for as long as you use them. FileJump's Lifetime Plan skips that model entirely, offering 2TB of cloud storage for a single payment of $59 (MSRP $467).
·bleepingcomputer.com·
Stop renting storage space — this lifetime 2TB plan is yours for $59
Microsoft to stop Exchange 2016 / 2019 security updates in October
Microsoft to stop Exchange 2016 / 2019 security updates in October
Microsoft has reminded customers that it will stop shipping security updates for Exchange 2016 and 2019 through the Extended Security Update (ESU) program in October.
·bleepingcomputer.com·
Microsoft to stop Exchange 2016 / 2019 security updates in October
Sovranità digitale e SASE: le domande che le aziende dovrebbero fare ai fornitori
Sovranità digitale e SASE: le domande che le aziende dovrebbero fare ai fornitori
La sovranità digitale non dipende solo da dove vengono archiviati i dati. Nel modello SASE entrano in gioco anche metadati, management plane, controllo operativo e governance tecnologica. Ecco quali aspetti valutare per scegliere davvero un fornitore affidabile
·cybersecurity360.it·
Sovranità digitale e SASE: le domande che le aziende dovrebbero fare ai fornitori
Se i chatbot fanno consulenza sull’aborto
Se i chatbot fanno consulenza sull’aborto
Le persone si affidano sempre più spesso ai modelli linguistici per ottenere informazioni e risposte sull’interruzione di gravidanza. Ma gli algoritmi che le forniscono attingono da un ecosistema di fonti dove autorevolezza e visibilità non sempre coincidono. E che le realtà pro-choice faticano a presidiare
·guerredirete.it·
Se i chatbot fanno consulenza sull’aborto
UK Cybercrime Journal: H1 2026 Dark Web Seizures & Arrests
UK Cybercrime Journal: H1 2026 Dark Web Seizures & Arrests
What Happened Nemesis Dark Web Drug Dealers Arrested On 14 May 2026, two Cambridgeshire drug dealers were sentenced after being arrested in...
·blog.bushidotoken.net·
UK Cybercrime Journal: H1 2026 Dark Web Seizures & Arrests
La cyber security delle piattaforme di collaborazione
La cyber security delle piattaforme di collaborazione
Sempre più centrali nelle operazioni aziendali, le piattaforme di collaborazione non sono esenti da rischi. Che tendono a essere proporzionali all’aumento del volume dei dati scambiati e alla crescita della superfice d’attacco. I rimedi da prendere in considerazione
·cybersecurity360.it·
La cyber security delle piattaforme di collaborazione
Chick-fil-A discloses data breach after credential stuffing attacks
Chick-fil-A discloses data breach after credential stuffing attacks
American fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks.
·bleepingcomputer.com·
Chick-fil-A discloses data breach after credential stuffing attacks
OpenAI says its AI models hacked Hugging Face during testing
OpenAI says its AI models hacked Hugging Face during testing
OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment.
·bleepingcomputer.com·
OpenAI says its AI models hacked Hugging Face during testing
LG to Ban Residential Proxies from Smart TV Apps
LG to Ban Residential Proxies from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers…
·krebsonsecurity.com·
LG to Ban Residential Proxies from Smart TV Apps
Police dismantle Kratos phishing platform, arrest developer
Police dismantle Kratos phishing platform, arrest developer
Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia.
·bleepingcomputer.com·
Police dismantle Kratos phishing platform, arrest developer
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
A large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads.
·bleepingcomputer.com·
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
Critical SharePoint RCE flaw exploited to steal machine keys
Critical SharePoint RCE flaw exploited to steal machine keys
Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched.
·bleepingcomputer.com·
Critical SharePoint RCE flaw exploited to steal machine keys
Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak
Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak
The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola's Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom.
·bleepingcomputer.com·
Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak
Identity & Access Management e approccio Zero Trust: la governance degli accessi logici
Identity & Access Management e approccio Zero Trust: la governance degli accessi logici
Per proteggere l'identità digitale aziendale nell'era del lavoro distribuito la strategia più efficace per garantire una governance solida e scalabile degli accessi logici consiste nell’adottare un sistema di Identity & Access Management (IAM) unito a una filosofia Zero Trust. Ecco come e perché
·cybersecurity360.it·
Identity & Access Management e approccio Zero Trust: la governance degli accessi logici